A cyberattack on Arizona's court system stole the personal information of more than 1.3 million people — and investigators believe it began when a court employee clicked a malicious link in an email. The Arizona Supreme Court confirmed the breach on Tuesday, revealing that attackers copied decades of records, including orders of protection and foster care case files, from a backup server on September 24.
The scale of the breach makes it one of the largest attacks ever to hit a US state court system, and the latest in a string of cyberattacks targeting American judiciaries this year.
How the breach unfolded
According to the Arizona Supreme Court, technology staff spotted the intrusion on September 24 and shut it down on a backup server about two hours later. The attackers had gained access through a phishing email clicked by a court employee — a single lapse that opened the door to millions of sensitive records.
The copied data centered on the court's Fines/Fees and Restitution Enforcement Program, covering roughly 1.3 million people with unpaid court fees, fines, and restitution payments for traffic and criminal violations dating back as far as 30 years. The attackers also took:
- Nearly 30,000 active and inactive orders of protection, including records tied to domestic-violence cases
- More than 150,000 reports from the Arizona Foster Care Review Board dating back to 2010, covering cases where parents were alleged to be unfit or unable to care for a child
The foster care records included general case information, child details, names and statements of interested parties, and recommendations made to the court.
"No evidence it has been used or shared"
State Supreme Court spokesperson Alberto Rodriguez said Tuesday that investigators have found no evidence the stolen data has been misused or shared since the attack. The breach is under investigation, and the court has begun notifying those affected.
Officials were keen to stress what was not compromised: no records were altered or deleted, the attack has not affected or delayed any court cases, and the attackers did not steal information about jurors, witnesses, or court employees.
Chief Justice Ann Scott Timmer said in a September 25 statement that the court's IT team stopped the attack as quickly as possible, and that she had spoken with the state's top FBI leader about the incident.
A widening pattern of attacks on US courts
The Arizona breach is the latest in a string of cyberattacks on state and federal court systems. In September, Montana Supreme Court Chief Justice Cory Swanson announced that Montana's judiciary had suffered "unauthorized access" to its case management and electronic filing systems.
The trend has cybersecurity experts warning that courts — which hold troves of deeply sensitive personal, financial, and family records — have become prime targets, often with IT budgets far smaller than the attackers they face.
A phishing email in Arizona, a compromised case-management system in Montana: the methods are basic, but the consequences are enormous. As this month has already shown with the breach of Denmark's CPR registry exposing 8.8 million records, public institutions holding population-scale data remain under relentless pressure.
Frequently Asked Questions
What data was stolen in the Arizona court breach?
Personal information for about 1.3 million people in the court's fines, fees, and restitution enforcement program, spanning records up to 30 years old, plus nearly 30,000 orders of protection and 150,000 foster care review board reports dating back to 2010.
How did the attackers get in?
The Arizona Supreme Court says the attack is believed to have started when a court employee clicked a malicious link in a phishing email. The intrusion was detected on September 24 and shut down on a backup server about two hours later.
Has the stolen data been misused?
According to court spokesperson Alberto Rodriguez, investigators have found no evidence the stolen information has been used or shared. The attack is still under investigation.
Are court cases affected?
No. The court says no records were altered or deleted, no cases have been delayed, and data on jurors, witnesses, and court employees was not stolen.
Why are courts being targeted?
Courts hold vast quantities of sensitive personal and financial records, making them attractive targets for attackers seeking data for identity theft or extortion — often against institutions with limited cybersecurity resources.
Original reporting: Associated Press via The Manila Times; additional context from Bloomberg Law and SecurityWeek.



